pull down to refresh

I don't see a version of this which ended without funds being stolen. A seed generated on a flawed Coldcard is permanently weak, so responsible disclosure had nowhere to go.

I've written up the technical failure, why I don't buy blaming AI, and why I think the "you were never really self-custodying" line is so misguided.

I really like this article. You do a nice job of explaining things clearly and I really like where you take it. Blaming this on AI is definitely scape-goatism:

the reality is almost too mundane to believe.
Pointing the finger at “a complex and subtle series of bugs” (to quote their postmortem), or at AI (for assisting in discovery of the issue) is an abdication of responsibility.
This was a build flag that didn’t do what its author thought it did. Human error, hiding in plain sight.

And I especially appreciated the latter half of your article. I agree with this:

More people should’ve verified Coldcard’s code for themselves, absolutely. But have you studied the Bitcoin source code line by line? No? Then you’re trusting it, not verifying it for yourself. And that’s fine - for 99% of people, some degree of trust is unavoidable.

I wonder though if it wouldn't be better for Bitcoin if the expectation was that influencers who accept sponsorship money retain a little more objectivity. I've never been sponsored to do anything, so I can't quite say how it feels, but I'm sure there is a lot of pressure to refrain from saying negative things about the sponsors products. Hopefully this incident is so bad that influencers are more willing to be critical.

reply

You cannot blame AI. AI isn't self-aware. It isn't "doing" things, humans are.

What you can state is that there is debt that was clearly not evident pre-AI and is becoming that now. Note that @Rob1Ham was talking about multiple vulns, not "found nothing". All that is debt.

reply

Thanks @Scoresby. I agree with you re objectivity, but I've never been sponsored either - my site's got no ads/affiliates etc.

I expect that fear of losing sponsorship (i.e. one's income) is partly why so many influencers / podcasters remained silent while nvk acted like a dick to others (as @raw_avocado said). Not excusing this - obviously he should've been held to higher standards - but it's easier for me to call out bad behaviour after his downfall than before.

reply

I hope you didn't read my comment as directing any criticism at you or your site. The site is excellent and it was not my intention. My comment about the expectation of influencers who accept sponsorship money retaining objectivity was aimed at the Odell's and Marty Bent's of this world, not at you at all. I'm terribly sorry if it doesn't read this way.

reply

No offence taken at all! I was just rambling and worded it badly. I get your meaning, and thanks for kind words.

reply
I wonder though if it wouldn't be better for Bitcoin if the expectation was that influencers who accept sponsorship money retain a little more objectivity.

Yes, and more humility and integrity. You don’t have to say things you don’t believe and you don’t have to believe what you’re told.

We’ve only ever had one small sponsorship and we were completely open about why we thought people should be cautious with them. If your sponsor has any integrity, they won’t mind that honesty. If they don’t, then…

reply
201 sats \ 0 replies \ @Aeneas 4 Aug

I read this article when you first put it up and thought it was great. It's especially true that, once the fuckup was made, it was already over and disclosing it would've led to chaos.

The one thing I'll say is about the idea they did everything right, and it's more for future reference because we have to learn things from this.

Darthcoin has always said, "Be your own bank — Think like a bank." Which also means thinking like whoever's in charge of vault security, and also like the armed guard up front. Banks have layered security.

Now for instance:

  • Having your entire stash in one single wallet?
  • No passphrase? Or a weak passphrase?
  • Having a very very very large stash, protected in this one little place?

Wouldn't we recognize these as mistakes, even if this had never happened? What if you get wrench attacked? What if your seed (in whatever stupid way you imagine) gets exposed? And it's well known (at least here on SN) that the hardware wallet itself can draw unwanted attention versus other, totally inconspicuous options like a normie laptop or USB setup.

This doesn't impact how we speak to newbs. A young guy can spend some time in lightning and Sparrow before moving to cold storage; it doesn't have to be overcomplicated and you can organically harden your security as you go.

reply

This incident showed us that "don't trust, verify" also applies to the RNG.

reply

you could sweep the funds yourself and return them minus a finders fee.

re "A seed generated on a flawed Coldcard is permanently weak, so responsible disclosure had nowhere to go."

reply